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(57) A method is provided for achieving admission control to a public connectionless packet network. This 
provides a method of access control which allows service differentiation in a form wtiich permits a user to 
receive a quality of service guarantee which is better than a "best effort" service. Each transmission by a user 
across the network includes a ticket message sent to the user from the network in response to a network 
resource (eg bandwidth) reservation request from the user. The required bandwidth when available during 
one time interval, is allocated for that interval and reserved for an immediately following interval. The ticket 
messages includes information about the priority level of the transmission, and can be used in a 
connectionless network to determine the resources available for future transmission requests. 
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At least one drawing originally filed was informal and the print reproduced here is taken from a later filed formal copy. 
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2331659 

RESOURCE RESERVATTON 

TECHNICAL FIELD OP THE INVENTION 

This invention relates to the field of resource 
reservation, and in particular to a method of 
5 controlling access to a communications network, and to 

components of a network using such a method. 
DESCRIPTION OP RELATED &PT 

The Internet is a communications network which is 
becoming widely available. The Internet provides a 
10 -best effort" bearer service. That is, the user 

receives the best service available at the time he 
requests it, but no commitments are given to the user 
in terms of available bandwidth, transit delay, or 
packet loss. The Internet is particularly useful in 

15 data communications applications, but is of limited use 

for telecommunications applications which require 
guaranteed bandwidth availability, and specify maximum 
values for the transit delay and loss of data. The 
Internet cannot usually guarantee the required quality 

20 of service. 

One conventional way of achieving resource 
reservation, to be able to provide a required quality 
of service commitment, is to use connection states to 
store information in the network nodes about bandwidth, 
25 buffer parameters, connection identity and status. 

However, an advantage of the Internet is that it is a 
connectionless network, which therefore cannot use this 
technique without sacrificing the simplicity of the 
Internet . 

One conventional way of achieving bearer service 
differentiation, in a connectionless network, is to use 
a set of priority bits in the packet header. However, 
in a public connectionless network, it is still 
necessary to control how many connections use the 
35 highest available priority. if every connection uses 

the highest available priority, the network can still 
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in effect only offer a best effort S ervice to the 

""^ problem remains, therefore, as to how to control 
admission to the network. 

s ^mim^^m^^ ths problem 

The prese « — nt,on see ks reservation 
of achieving admission control ana 

in a -^^r^rl^ion, each transmission by a 
S er r/rlss The n^rk includes a message sent to the 
10 U u rom the network. The message includes 

Nation about «- ^ ^with the 
transmission based on the user ^ by 

network provider, and can sue y 
xs the network to determine how to handle the 

transmission. network being able 

Thus, rather than rely on re levant 
,. = of the connection, tne re« 

to detect the status of tne ^ 
information is transmitted by ^the^user^^ ^ _ 

20 transmission, and can 

required. information can be 

rr, nref erred embodiments, tnis im 
in preferre routing purposes. 

used for admission control and 

25 re™,:-:: - * e by way of 

to the accompanying drawings. 

£ re P resentation of a 
u ^ accordance with the invention. 
30 net "°;U« nilustrates the flow of signalling 

in a£ - co rdance with the invention. 
m essages in ^* cha „ indicat ing the steps 

^ A„ accordance with the invention. 

taken F rgu:e m : i 0 s a .rascal representation of an 
" edmisllon control procedure in accordance with one 
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aspect of the invention. 

Figure 5 illustrates a ticket protocol in 
accordance with an aspect of the invention. 

Figure 6 illustrates a network operating m 
accordance with an aspect of the invention. 

Figure 7 illustrates a network operating in 
accordance with another aspect of the invention. 
zrj-jirr DgsssizriSN of ppffffffp embodiments 

Figure 1 represents a network in accordance with 
the invention. In Figure 1, a user at terminal A 
intends to send a message, in the form of data packets, 
to terminal B across the Internet. The Internet 
includes a large number of nodes, of which only a small 
number are shown in Figure 1. These are designated 
real-time routers RR, while the node to which the 
terminal A is connected is designated the access router 

AR - _ 

in accordance with preferred aspects of the 

invention, each node in the network, including users 
who may wish to send or receive data packets, has an 
internal clock. The clock at each node is used to 
measure time slots of size TO seconds, where TO is an 
arbitrary period of perhaps several seconds, chosen to 
be reliably greater than the maximum network transport 
delay. The nodes and terminals are synchronized to the 
network clock reference. 

As described herein, it is assumed that the 
network is able to support resource reservation from 
end to end. However, it will be appreciated that the 
invention is equally applicable when resource 
reservation is only available over a specific network 
domain, covering only a part of the end to end path 
in such a case, the reservation protocol is terminated 
by the routers at the edges of that network domain 

' Resource reservation for a user data flow may be 
supported by different types of reservation protocols 
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along the end-to-end path of the flow. For example, 
the protocol according to an aspect of the invention 
may be used over a specific network domain, covering 
only a part of the end-to-end path. An interworking 
5 function is then needed between the network domain 

supporting the protocol according to the invention and 
adjacent network domains using other types of 
reservation protocols. As a special case, an arbitrary- 
type of reservation protocol can be used for the 

10 signalling between the user and the access node, while 

the network internal signalling is performed with the 
protocol according to the invention. The interworking 
function between the two types of reservation protocol 
is then located in the access node. 

15 Although the invention is described herein with 

reference to the Internet, it is applicable to any 
connectionless packet network, whether public or 
private . 

In accordance with preferred embodiments of the 

2 0 invention, the sender has a traffic contract with its 

network provider, under which a particular quality of 
service is guaranteed. This allows the network 
provider to offer service differentiation to users. 
Thus, users who are prepared to pay higher charges are 
25 able to guarantee access to higher bandwidths, or 

higher priority traffic handling. 

The flow of signalling messages during a data 
transmission will now be described with reference to 
Figure 2, while the steps taken in the access router AR 

3 0 will be described with reference to the flow chart of 

Figure 3 . 

When the sender wishes to initiate a data 
transmission, a user resource reservation request REQ-U 
is sent from the terminal A at point PI in Figure 2 , 
3 5 and received at the access router AR in step 1 of the 

method of Figure 3. The resource reservation request 
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specifies the required bandwidth for the transmission 
the required traffic class, the source address and the 
destination address. These parameters are thus set for 
the duration of the transmission at this stage. 

in step 2 of the method, it is determined at the 
access router AR whether the resource reservation 
request passes the admission control. This admission 
control is performed in a way which is described in 
more detail below. if the resource reservation request 
does not pass the admission control, the request is 
denied. 

As described in more detail below, the information 
needed for admission control is not stored in the 
network on a per connection basis, but can be extracted 
by the network as required from messages associated 
with every transmission which gains access to the 
network. Thus, these messages must contain all 
information which is necessary to allow the network 
nodes to perform admission control and policing of the 
20 transmission as required. 

If the resource reservation request passes the 
admission control, the method passes to step 3 at point 
P2. Here, the access router AR sends a network 
resource reservation request REQ-N across the Internet 
25 to the terminal B. Each node in the transmission path 

can perform resource reservation and admission control. 
For example, at point P3 , admission control is carried 
out by the node RR. if the required bandwidth is 
available across the network, an acknowledgement ACK is 
sent from the terminal B to the access router AR at 
point P4, and received in step 4 of the method. 

Following receipt by the access router AR of the 
acknowledgement message ACK, required information about 
the state of the connection is passed from the network 
to the user A at point P5 and in step 5 of the method. 
Specifically, information about the resources allocated 
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a nd other connection parameters (for 
to the connec tion 4 , 

example those " ^ ^ th£ sender A in a 

sent from the acces on in th e ticket 

cick et message £ * ^ fay , digical 

mSSS Ture to prevent its alteration by the user A. 
^calculation of the digital signature is 

described *™J££ £7 which is similar 

The ticket «»•■•»■ „ hich can be added to 

in some ways to acr oss a 

a packet header befor che ticket message 

connectionless network^ Howe dete rmined by 

US ed in accordance with the ^ ^ 

the network lts *"' , service which is in- 

ensure that users receive sarvice guarantees, 

accordance with their quality of serv ^ 

. users cannot reserve 

and ensures that use goJir » M .d. 
resources whrch go beyo ^ 

In one en.bodi.ent the ^ ^ 

priority bits in . convey ^ trans mitted by 

message, determined by the ^ 

^T-T^r set by the user for a particuiar 

message Tl, sent in step ^ ^ £or the ti 

Pigure 3 is sent at time ^ ^ as wlll 

slo t of duration T 0 from also 

he described in more detail b . ^ ^ 

all ows the node A to reserv ^ ^ ^ 

subseo.ent time in mo re detaii beiow 

"^er tTthe admission controi which is 

performed at the node A*; messaqe M l, the sender A, 

• ^-f t-Vip txcket message 
at pctltTln^. sends a data packet, together 
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with the ticket message Ml. 

At point P7 in Figure 2, and in step 7 of the 
method, the node AR is now able to police the data 
packet, by confirming that it complies with the 
5 original request REQ-U, in respect of which the ticket 

message Ml was issued. 

Assuming that the data packet does comply with the 
requirements specified in the ticket message, it is 
transmitted in step 8 of the method to the subsequent 
10 node RR, and hence to the receiving terminal B. 

At point P8 in Figure 8, the receiving terminal B 
sends an acknowledgement message ACK, which is returned 
to the access node AR, and received in step 9 of the 
method. 

15 At point P9 in Figure 2, and in step 10 of the 

method, a further ticket message M2 is then returned to 
the sending terminal A. This ticket message M2 is 
valid for the time slot from time Tl until T2 , and 
effectively reserves band width for the subsequent time 

20 slot from time T2 until T3 , as discussed above with 

reference to the message Ml. 

The process then cycles until such time as the 
sending terminal A has completed transmission- Thus, 
in step 11 of the method, a further data packet 

25 containing the ticket message M2 is received at the 

node AR . 

The method for performing admission control at a 
network node will now be described in more detail. In 
accordance with the invention, admission control is 

3 0 performed in each node of the network. Admission 

control is carried out on the basis of policy rules 
(for example, does the sender have a service contract 
which allows him to send a specific message type to a 
particular destination at a particular time) , and on 

35 the basis of availability of resources. Admission 

control on the basis of policy rules is carried out in 
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a conventional way. while admission control on the 
has" of availability of resources is described further 

mentioned above, each node in the network has 
an internal clock, which works on the basis of txme 

c;lots of length T 0 - 

in one embodiment, the phase of the periodical 
transmission of ticket messages from terminals is 
synchronised to a common reference, and the beginnings 
S the time intervals within the network nodes are 
10 Synchronised to the same reference. Moreover, the time 

Tot length is chosen to be 
case network transport delay. In thxs way, a 
can be transmitted at times which guarantee that they 
Arrive at network nodes at a safe distance from the 
" r d ^ of any time slot, thus ensuring that the tickets 

will be received within the intended time slot It 
this situation which is illustrated in Figure 2 
thxs sxtua altern ative embodiment, the clocks 

However, in an aiiemai-i 
• -vw, different nodes need not be synchronised. 
20 ^ described above, a ticket message issued from 

an access router to a sending terminal comprises m 
ef f ect a permission to transmit a packet with a 
specific band width at priority level until the ticket 
2S Spires. The ticket is typically valid for one time 
slot which may for example have a duration of a few 
seconds. In the event that the user wishes to transmit 
' " for a l0 nger period, it is undesirable to force 

30 with the associated risk that the request would be 

denied if resources were unavailable. Rather, in 
accordance with the invention, a user having an 
established reservation has a higher Rew 
r enewing that reservation, than a user requesting a 

" ^Thus^s described above with reference to Figure 
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2, each ticket message Ml, M2 , M3 , transmitted from the 
access router AR to the sending terminal A is itself 
valid for a current time period in order to prove that 
resources have been reserved for that time period, but 
is also valid to make a resource reservation for the 
immediately subsequent time slot. 

When the sending or receiving terminal wishes to 
terminate the reservation, a received ticket message 
can simply be discarded, and not returned to the access 
router. The loop is thus broken, and no new tickets 
are issued. The links along the path from sending 
terminal to receiving terminal will then calculate a 
decrease in the reserved bandwidth, and will thus be 
able to allocate more bandwidth for new resource 
15 reservations. 

Alternatively, if a sending terminal wishes to 
release bandwidth which has been reserved, it can send 
a release ticket message to the access router at any 
time . 

20 In addition, if, for any reason, a sending 

terminal does not receive a new ticket at an expected 
time, it transmits with its next packet of data a non- 
acknowledged ("NACK") ticket message in its place. 
This ticket NACK contains exactly the same information 

25 as the previously transmitted ticket. For the purposes 

of bandwidth reservation, one such non- acknowledged 
ticket message NACK can be treated as a valid renewal 
request . 

We can define an admission decision rule for the 
3 0 nodes in the network. Assume that a node gets a 

request for bandwidth B r on a link during time slot t n , 
i.e., it is necessary to decide whether to admit the 
flow for time slot t n . The admission decision is made 
on the basis that: 
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- B, - B a (0 - B re ,(0 * B,M \% y £ 



where 

B is the maximum bandwidth that can be 

supported on the link. 
B (t n ) is the total new bandwidth admitted on the 

5 link for time slot t n . 

B req (t n ) is the requested and admitted bandwidth so 

far on the link for time slot t n . 
B re i(t n ) is the bandwidth on the link released so far 
for time slot t n . 
10 Thus, the decision rule only depends on the 

internal time intervals within the nodes and the 
decision rule is the same, independent of whether the 
network is synchronised or not. Furthermore , this rule 
gives a "yes" if and only if indeed the requested 
15 bandwidth can be supported by the link. 

Thus, the node stores link states, each containing 
the aggregate reserved bandwidth on a link, but does 
not store the reserved bandwidth allocated to a 
particular connection, although it can obtain this 
20 information from a ticket message sent on the 

connection. 



Then, let 



and let 



BM = B a (t n ) - B m (t n ), 



BJ.0 = W - W = °- 



We update B a at the end of time slot t n as: 



25 where: 
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B m (t n ) is the bandwidth on the link measured from 

the "renew" and "NACK" tickets during time 
slot t n . 

B nack(t n ) is the total bandwidth on the link from 
"NACK" tickets during time slot t n . 
The result is that, if a sender stops sending 
tickets and there are no lost tickets deeper in the 
network, the bandwidth is released after two internal 
time intervals in all the nodes. This works 
independent of the clocks of the different nodes . 

The reason for using max (0 , B A <t n _ x ) - B nack (t n )) to 
update B a (t n+1 ) instead of just B^t^J - B nack (t n ), is 
that if some bandwidth measured at the node is 
associated to a ticket which is lost deeper in the 
network, B A {t n . 1 ) - B nack (t n ) might be greater than zero. 
If this is the case we should obviously not reserve 
more bandwidth than we already have reserved. 

This form of admission control is illustrated 
graphically in Figure 4 . 

In the example of Figure 4 the vertical axis 
represents the current estimate of the admitted 
bandwidth, while the horizontal axis is the time axis. 
The time at the particular node is divided into slots, 
as previously discussed, with the end points of the 
slots being designated TO, Tl, T2, and so on. Thus, in 
Figure 4, each rectangle represents a reservation or 
reservation request, with the height thereof 
representing the bandwidth required. White rectangles 
represent reservation requests, while shaded boxes 
represent allocated tickets which reserve bandwidth 
during a particular time slot. 

Thus, in Figure 4, at point tA, a bandwidth 
reservation request is received, and this remains valid 
for the time until TO, and for the whole of the 
subsequent time slot until Tl . At time tB, a second 
reservation request is received, and this remains valid 
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until the next end point Tl, and for the whole of the 
subsequent time slot until time T2 . A third 

id received at txme tC, and, at 
reservation request is received a 

each of these points, the estimate of admitted 
Ldwidth is updated to include bandwidths revested in 
the most recently received reservation request. 

At time tD, a fourth reservation request is 
admitted, but the required bandwidth therefor is such 
tbat to admit that flow would result in the estimate 
^admitted bandwidths exceeding the maximum bandwidth 
for that particular traffic class. Thus, the fourth 
reservation request is not admitted. 

At end point Tl, the ticket issued in respect of 
reservation request A becomes valid, and so, for the 
HmHlot from Tl until T2, the bandwidth estimate is 
"ased on the bandwidth allocated by that ticket, and by 
the reservation request B and C. 

.urine the time slot from T 2 until T3 . tickets or 
the three flows A. B and C are all valid. At t » T3 
ticket loop A stops, and so the estimate of admitted 
I ndwldths'falls. Similarly, at time « ^ loop C 
s to P s. and the estimate of admitted bandwidth falls 
again Finally, at time T5. ticket loop B stops, and 
the estimate of admitted bandwidth falls to zero. 

The discussion of admission control above has been 
on the basis that the network nodes are ^ h ™ d ' 
However, as previously mentioned, the method and 
apparatus of the present invention may allow the use 
a non-synchronised network, by an appropriate 
"edification of the ticket messages. To achieve this, 
each node in the network works with internal time slots 
which are alternately designated "0- and "1". When a 
wnicn aie h includes in the 

node receives a ticket request, it then mclu 
ticket a synchronisation bit which corresponds to the 
designation of the time slot in which 

request has been received. This ensures that, althoug 
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the different nodes in the network are not synchronised 
with each other, it is always possible to deduce the 
time slot in which a request has been received. The 
lack of synchronisation may mean that it is otherwise 
not possible to tell in which of two adjacent time 
slots a request has been received, but the 
synchronisation bit will always allow that distinction 
to be made . 

If a resource reservation request is allowed, that 
is, it passes the admission control, a ticket is issued 
as mentioned above. 

The ticket protocol, defining the form of the 
ticket, will now be described in more detail with 
reference to Figure 5. As will be apparent, the ticket 
needs to include source and destination addresses and 
an indication of priority in the IP-header, but must 
also contain other relevant information, which is 
preferably set out in a format as shown in Figure 5, 
and as described below. 

Counter 8 bits wide. A counter filed initialized 
to zero and incremented at each node where a 
synchronisation bit is used. This field is used for 
the nodes to find the correct synchronization bit. 

Length 8 bits wide. The length of the 
Authentication data field in 32 bit words. 

Signal 8 bits wide. Information of type of ticket 
message . 

Synchronization bits 40 bits wide. The 
synchronisation bits used by the nodes. This implies 
that a maximum of 4 0 admission nodes can be used for a 
non synchronised network. 

Bandwidth 3 2 bits wide. The reserved bandwidth 
over the link. 

Authentication data. The length of this field is 
variable, but is always an integral number of 32 -bit 
words . 
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If only the access node uses the authentication 

AM it would be convenient to only use a 32-bit 
data it woux g ^ uge 

use! as a stock where each node which uses an 

• -i~n data field either add or remove the 

:::: u, «- — 

n^Hcation tag should be 32 bits, 
of an authentication u » j..,,,,! n ck et 

A method for calculating the digital ticket 
matures is now described. As mentioned above, all 
signatures is jatMi-l time slots, and 

rcc^e tr slots of the access node are designated 

::, »,.*..« «~» - * duration ° f time 

To 



Each node, which wants to be able to put a 
.ionature to a ticket, holds one general key and one 
signature r o£ cime keys is 

Se " eS "d and kept internally within the node, and 

fe^r trans^tfed to any location outside the node^ 

Z LnLal key is denoted by k and the time dependent 
The general key ^ interval t „ 

rs'ssL ated'w th a 'specific key k. «- - «- 

^message to be protected are ^ - and 
, h(l tick et signature associated with this ticket 

TZ s Thus, an authenticated ticket message 

""Tbv a real time node at slot t n consists of m 
issued by a real t ^ ticket 

concatenated with s„, i.e.. lm, sj.. i a 

• v arrives at the node time interval t B we 
ra essage which arrives at th ^ 

use the keys k and k^ to sign tne z. 

Let f be the signing function, thus, 

The signing function f can be chosen using the 
liic oj-^ r rrpr and M.N- 

authentication method proposed in J.L. Carter 
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Wegman, -New hash functions and their use in 
authentication and set equality" , Journal of Computer 
and System Sciences, vol. 22, pp. 265-279, 1981 or 
B. den Boer, "A simple and key- economical 
unconditionally secure authentication scheme", Journal 
of Computer Security, vol. 2, pp. 65-71, 1993, and 
T. Johansson, G. Kabatianskii and B . Smeets, "On the 
relatxon between A-codes and codes correcting 
independent errors", Proceedings of Eurocrypt '93, ln CS 
765 Springer-Verlag, „ ml . ll§ 1993 . The latter ^ 
is briefly described below. 

Assume that we can rewrite m in the following way 
» (m lt m 2/ . .., mj , where each m L e CF(2 r ) ± e an 
element in the finite field consisting of r'bits."' if m 
not xs a precise multiple of r bits we may assume that 
we pad 0 bits to m such that the length equals a 
multiple of r. Furthermore, assume that k 1# k € 
GF(2*) . now, we use the following formula to calculate 
S« € GF (2 r ) : 

S " = Am > *' k n+i> = k „*i + «i • k + m 2 ■ k 2 * ■ • • + m t . k i m 

This gives a probability for anyone, who only 
observes one signature signed with k„, to succeed in 
changing m without detection by the access node, of: 

9 

T 

independent of the computing power of the adversary 

To verify a ticket signature at time period n, the 
node uses the keys k and k„ to verify the signature 
according to the formula above, i.e., it uses the 
present key to check a signature and the key for the 
next slot for calculating a new ticket signature. The 
key to be used is determined by the slot at which a 
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• te t arrives downstream at a node. Thus, in the case 
ticket arrives synchronised when the 

— r W °ts Its si^re Tthe ticket before 

access node puts its Sign 

forwarding it to the sender^ it has t ^ 
synchronisation bit to be able to 

5 X tor calculating ^J^'^^JL^ 

. ^ — the slot ciiue j-o 
corresponding to the ^ node may 

first arrived at the des tination addresses 

preferably protect the s ^ 

" - "I i;rUl ueeperln the -work which want 

signal field. N protect che sourC e 

to authenticate reserved bandwid th. 

and ^- i -"° n ; s f r f S a signature generated using a Key 
Thus, the use of ^ cime sloC allows the 

15 which is unique « « ^ ticket „as validly been 

node to verify tha • in which it is 

Issued in respect of the tim 

received. mi ht n ot have a 

"Tcr and duetothe transmission delay, the 
20 perfect clock and signatures 
access node should pref erab y 
calculated both with key k. and K. , a 

transition from time «»" al " J£ invent ion . the 
» accordance with aspects o the ^ ^ 

« use of ticket -sages - *~ _ ^ ^ to 

traffic flows m the eve network has 

recei ver must b. — termlne! » output post to 
a routing table, wnl destination must be 

which traffic for a frequently. 
^4- The routing tables ate ^ F 
3 0 sent. Tne ^ *.«ffie management 

failure. „,.„„,-]< a router immediately 

In a connectionless network a r 

35 re .routes all the traffic related to *P ^ 

in the routing table when that entry up 
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works for best effort traffic but is not allowed for 
already established connections with reserved 
resources, which first must pass an admission control 
along the new path. Therefore a mechanism must be 
introduced to prevent this immediate rerouting of 
traffic with reserved resources. 

In accordance with this aspect of the invention, 
prior to the replacement of an output link in a routing 
table entry, the traffic on the link is stopped by 
discarding all tickets, thus breaking the ticket loop. 
Moreover, the reserved traffic that is routed according 
to the changed entry is given the low priority of 
unreserved traffic. The user must thereafter initiate 
a new reservation request in order to reserve resources 
along the new path. 

The mechanism works as follows: suppose that the 
routing table changes from the "old" to the "new" set 
of router output ports in Table 1. As can be seen, the 
traffic that was previously routed to output port C is 
now routed to output port A or B. Since the traffic 
that has been rerouted has not passed any admission 
control on the new output ports, the ticket messages 
must be stopped, and the priority of the payload 
packets must be reset to the low priority of unreserved 
traffic . 
Table 1 



de s t ina t ion addr e s s 


old output port 


new output port 


destination address 1 


port C 


port A 


destination address 2 


port A 


port A 


destination address 3 


port B 


port B 


destination address 4 


port C 


port B 



This is achieved by introducing a temporary 
"switch-over" state for the entries in the routing 
table with a changed output port. Packets which are 
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routed according to the -switch-over" state are given 
the low priority of unreserved traffic and ticket 
Usages are dropped. The principle is illustrated in 
Table 2, which shows the routing table with the 
"switch-over" state. 
Table 2 




old output 
port 



switch-over state 



dest address 4 



port A + drop 
ticket, lower 
priority 



port C 



new output 
port 



port A 




port B + drop 
ticket, lower 
priority 



port B 



The switch-over state is kept until all ticket 
looos are broken, which takes two time intervals Ta, 
and is indicated by the absence of new ticket messages 
The ticket protocol is then ready to operate as normal 
according to the new routing table, and the switch-over 
ct . a fp will be terminated. 

since the ticket loop has been broken, the user 
who wishes to restore the reservation must do this by 
Issuing a new resource reservation revest which will 
be routed according to the new routing table ' 

in some cases the change of the routing table 
the result of a well controlled network management 
activity, where the operator has ensured that 
sufficient resources for the rerouted traffic are 
available on the new path. Then there is no need to 

or a new admission control and resource reservation 
to a , . H . ket loop as described 

nmredure by breaking the ticicet loop 

above The'switch-over mechanism should therefore be 
disabled in this type of controlled rerou ting^ The 
user data flow and the ticket messages are then 
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rerouted as soon as the routing table is changed. The 
resource reservation is controlled by the ticket 
message and will thus be installed on the new path 
Sxnce it is assumed that resources are available on the 
new path, no admission control procedure is needed when 
installing the new reservation, and there is thus no 
need for the user to send a resource reservation 
request message. The user does not have to be notified 
about the route change and just continues to send 
10 ticket messages as usual. 

in a network operating in accordance with aspects 
of the invention, the sender of the user data flow 
makes a resource reservation and will in most cases be 
charged for this reservation. It is therefore natural 
that the sender will have an interest in the 
performance of the network service. In order to 
deliver performance feedback to the sender the 
receiving terminal measures the performance of the 
received packet flow in terms of delay and packet loss 
The result of the measurement can then be delivered to" 
the sending terminal by inserting it in the ACK and 
txcket messages discussed previously and shown in 
Figure 2 . 

in accordance with aspects of the invention 
admission control and resource reservation are done on 
a hop by hop basis, i.e., the decision to accept or 
reoect a reservation is made locally by a resource 
management entity at each router. However, in some 
cases it may be advantageous to perform the resource 
management in a centralised manner. The introduction 
of resource management into a best effort network can 
then be achieved by adding a central resource 
management controller. The need for updating or 
replacing already installed routes can then be 
minimized, since they do not need to handle the 
admission control and resource reservation functions 
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The ticket protocol discussed above might be used 
• this tyPe of network as described with reference to 
„ this type a network operating in 

Figure*. Frgur invention. The 

accordance with an aspe o£ „ hlch cwo 

netwo rk is divided into ^ ^ g Each 

(subnet 1 and subnet ^gement controller 

subnetwork includes * reso " co receiv er B. the 

irssCr^ Z -ere are other nodes, or routers 
R - „„e reservation request REQ from the sender 

a is fo= e tr t he ^^xir^ 

and resource rese resource 
controller ^^^SU- Based on this 
reservations can perform admission 

information the con ^ ^ reservatio 

control, i.e. accep a accepted, the request is 

to Thl rer^retrrralon, the path .owaras 
rrstUtil. wbere th, = procedure is repeated « 
the resources have succe sf ^ ^ t will be 

way to the ^ stinatl ° n ' ^ t ^ the sender, and a 
turned to the access ^ ^ ^ 

"Tr TThe -dfr WU1 then periodically forward 

— * — . -«* * ~ — 

-u<=> f^rket message may ^vc « 
Mtematively the ticket and may 

of only one time slot, as Dack et, as described 

need to be renewed with each data packet, 
with reference to Figures 2 and 3 . tion o£ 

o P f whether a 

the ticket protocol is whether 
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basis . 



acroJ^" 13 £or " arded ^ optimum path 

across the network, and does not need to pass the 

resource management controllers. The ticket message 

so L r T ted V " r9SOUrCe — 3— t controllers 

so that they can keep track of the status of each 
connection. 

Alternatively, as shown in Figure 7, the ticket 

10 datT 3e The Ca a n e be ^ ^ ^ — P " h ^ -~ 

then 'not f r ° UCerS ** " eaCh -*~t«ork would 

then notify 1C s resource management controller KMC only 
when the ticket message indicates a change in the 
status of the connection. The latter alternative is 
advantageous for a large subnetwork where the resource 
15 management controller wouid be over-loaded by all "he 

ticket messages. By only sending a notification when 
the status of each connection is changed, the number of 
messages to the controller can be reduced. 
,„ " 311 Che CickeC usages are forwarded to the 

r:r i? then u - °— — 

T, . T -nnect.on. If only change . 
about the status of each connection are sent from the 
access router to the controller, then both the access 
router „ and the controller must keep states per 

z => connection. * 

It must also be possible for the resource 
management controller to terminate the reservation bv 
oreakmg the ticket loop. This is straio ^f , 
th^ straightforward when 

the tlC ket messages are routed via the controller as in 
>° Fxgura 7, since it can discard the ticket me ssage 

When the ticket messages are routed along with the 
data th e resource management controller RMC sends a 
notxfxcation to the access controller with an 
instruction to break the ticket loop for a specific 
connection by discarding the corresponding ticket 
message. 
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IC is important to note that the ticket protocol 
It is imp network is 

interf ace between the us " res ource management 

completely inde pendent of whether ^ ^ 
controller is used or her the network 

s matter for the network ce manag ement 

should be based on a ^"^J^, t o Figures 6 and 
-^J^rS^ - admission control 

operator can choose to or in a 

connectionless manner, as informat ion in the 

connection oriented mode. ' connection 

15 revest and ticket messages to^ ^ 

state for the data rx through 

i ^nsrator domains, can ^ 
through several °P erat ° r It may be 

networks operating bo^ modes. ^ ^ 
advantageous to use ^ ^ che rest of 

access router to upp connecti0 nless manner, 

the network operates in a allows 

There is thus described a syste 
nearer service differentiation in a conn 



network - 
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CLAIMS 



1 - A method of reserving network resources for a 
transmission, the method comprising: ^ 

at an access node in the network, receiving 
resource reservation requests from sending network 
users connected thereto, each resource reservation 
request specifying an intended destination and a 
bandwidth requirement; 

in response to each received resource reservation 
request, performing an admission control procedure- 

111 SVent that the resource reservation request 

Passes admission control, transmitting a request across 
the network to the intended destination associated 
therewith to allow other nodes to perform admission 
15 control procedures; 

in the event that the resource reservation request 
passes all admission control procedures to the intended 
destination, sending from the access node to the 
sending network user associated therewith a ticket 
message containing all necessary connection 
information; and 

allowing access to the network for a transmission 
from the sending network user when the transmission 
includes the ticket message, 

wherein the admission control procedure at the 
access node determines whether the required resource is 
available during a time slot by: 

determining what resources have already been 
allocated during said time slot, and what resources 
have already been reserved or requested, 

wherein sending a ticket from the access node to 
the sending network user during a time slot allocates 
the required resources for said time slot, and reserves 
the required resources for a second time slot 
immediately following said time slot. 

2. A method as claimed in claim 1, wherein, when 
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receives a transmission from the 
ch e access node ^ th e ticKet message, a 

sanding networ* user in ^ CQ 

sec ond ticket -^a^s sa _ ^ from 

ch e ^ n n ; d nf landing network .sa, during the 

TtiL stot allocates the retired resources for 
second time slot rese rves the required 

" ld lethodTr'ailo-ting bandwidth on a network 

U*. method --^^r^r^ during a 

required -d«id- : s — f- b r ndwidth is availab la. 
time slot and, if the r qu ^ ^ f<jr g 

a^ocating the — t^ - sa ^ ^ ^ 

cime slot reserving neCwor k resources for a 

trensmissiTfrom a first netwcrk user, the method 

comprising: f . slots based on a 

defining a succession of txme sio 

clock in the network a resource 

^^^^ —red resource is available 

on a link from said node; ne twork user 

sending from the network to the 

a ticket message; and network £or a transmission 

allowing access to the network 

sr. r: :r«:: ....... — 

•■"V" ; rr.." — s 

• slots at said node are denoted by 

successive time slots a cic ket message 

al temating binary values and th t ^ ^ 
includes a synchronization bl cor P 
binary value denoting a time slot in 
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tnessage was generated. 

6. A method as claimed in claim 4, wherein the 
ticket message includes a digital signature, calculated 
on the basis of a key which is used only during a time 

5 slot in which said ticket message was generated. 

7. A method of reserving network resources for a 
transmission from a first network user, the method 
comprising: 

receiving at a node in the network a resource 
10 reservation request from the first network user to 

initiate a reservation; 

confirming that the required resource is available 
on a first link from said node to a destination 
address; 

15 sending from the network to the first network user 

a ticket message containing connection information; and 
allowing access to the network for a transmission 

from the first network user when the transmission 

includes the ticket message, 
20 wherein, when it is determined that the link is no 

longer available and that an alternative link must be 

used, the ticket message is dropped. 

8. A method of reserving network resources for a 

transmission from a first network user, the method 

2 5 comprising: 

receiving at a node in the network a resource 
reservation request from the first network user to 
initiate a reservation; 

confirming that the required resource is available 

3 0 on a link from said node; 

sending from the network to the first network user 
a ticket message containing connection information; and 

allowing access to the network for a transmission 
from the first network user when the transmission 
35 includes the ticket message, 

wherein it is determined whether to allow access 
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to Che network on the basis of resources allocated by 
previous ticket messages, and 

wherein the ticket message remains valid for a 
redetermined time period such that, in the event of a 
Network error, the resources ailocated thereby are 
"leased after expiry of the predetermined time period^ 
9 a method of reserving network resources for a 
transmission from a first network user, the method 

, ^receiving at . node in the network a reaource 

reservation request from the first network user to 
initiate a reservation; 

confirming that the required resource is available 

on a link from said node; 
s sending from the network to the first network user 

5 a ticket message containing connection information; and 

allowing access to the network for a transmission 
from the first network user when the transmission 
includes the ticket message, 

the ticket message being valid for one time slot, 
as defined by the network, and including a 
signature, calculated on the basis of a key whach is 
used only during a time slot in which said ticket 
m essage was = ^ ^ ^ ^ m , , wherei n when 
a transmission including the ticket message has been 
complete, the network sends to the first network user 
a second ticket message containing connection 
information, the second ticket message being valid for 

on a further one time slot. 

11 A method of reserving network resources for a 
transmission from a first network user, the method 

^"receiving at a node in the network a resource 
35 reservation request from the first network user to 

initiate a reservation; 
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confirming that the required resource is available 
on a link from said node; 

sending from the network to the first network user 
a ticket message containing all necessary connection 
information; and 

allowing access to the network for a transmission 
from the first network user when the transmission 
includes the ticket message, 

wherein the determination as to whether the 
required resource is available on the link is made at a 
central resource controller. 

12. A method as claimed in claim 11, wherein the 
central resource controller controls the allocation of 
resources within a subnetwork made up of a plurality of 
nodes . 
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